TL;DR
A critical Artifactory authentication bypass vulnerability allows unauthenticated threat actors to obtain administrative privileges. Security researchers warn that this severe weakness is currently exploited in the wild. JFrog rates it 9.8 on the CVSS scale.
- CVE: CVE-2026-82329
- CVSS: 9.8 (Critical · CVSSv3)
- Product: jfrog artifactory
- Affected: < 7.111.21, 7.117.0, 7.125.0, 7.133.0, 7.146.0, 7.161.0
- Impact: Potential authentication bypass leading to administrative access in Artifactory
- Status: No confirmed exploitation yet
- Patched in: 7.111.21, 7.117.28, 7.125.20, 7.133.29 (+2 more)
- EPSS: 0.4% (30-day)
- Action: Update to 7.111.21, 7.117.28, 7.125.20, 7.133.29 (+2 more) now
Why It Matters
JFrog Artifactory operates as a vital central repository for corporate software components, container images, and deployment packages. Threat actors who obtain administrative privileges can alter source code, inject malware, or steal sensitive intellectual property. WatchTowr Intel recently reported that CVE-2026-82329 is actively exploited in the wild by adversaries minting unauthorized admin tokens. A compromised repository threatens the entire organizational software supply chain, potentially exposing downstream clients to poisoned updates.
How the Attack Works
This critical flaw exists due to a fundamental authentication weakness within default deployment configurations. An unauthenticated attacker with basic network access transmits a maliciously crafted payload directly to the vulnerable endpoint. This specific action bypasses standard identity validation mechanisms entirely. Consequently, the targeted system grants the intruder full administrative access without requiring valid credentials or user interaction. Attackers can then freely manipulate user accounts and system settings.
Affected Versions
The Artifactory authentication bypass vulnerability impacts multiple self-hosted release branches:
- Versions 7.161.0 through 7.161.19
- Versions 7.146.0 through 7.146.36
- Versions 7.133.0 through 7.133.28
- Versions 7.125.0 through 7.125.19
- Versions 7.117.0 through 7.117.27
- Versions 7.111.4 through 7.111.21
Patch or Mitigation Steps
JFrog proactively fortified all affected cloud environments, requiring no action from cloud customers. To resolve this Artifactory authentication bypass, administrators managing self-hosted environments must upgrade their instances immediately. Available fixed releases include versions 7.161.20, 7.146.38, 7.133.29, 7.125.20, 7.117.28, and 7.111.21. Organizations unable to patch immediately should restrict administrative network access to trusted internal IP addresses. Network defenders must also check logs for unauthorized token generation.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!